Логотип exploitDog
bind:CVE-2024-50861
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-50861

Количество 3

Количество 3

nvd логотип

CVE-2024-50861

около 1 года назад

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-50861

около 1 года назад

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable t ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-mx7x-mmcr-wf43

около 1 года назад

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-50861

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.

CVSS3: 6.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-50861

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable t ...

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-mx7x-mmcr-wf43

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.

CVSS3: 6.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу